Nas Proxy Server
by Qnap
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-7637 | Cri | 0.64 | 9.8 | 0.03 | Jun 5, 2018 | QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges. | ||
| CVE-2017-7635 | Hig | 0.57 | 8.8 | 0.01 | Jun 5, 2018 | QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections. | ||
| CVE-2021-34359 | Med | 0.45 | 6.9 | 0.01 | Feb 25, 2022 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS… | ||
| CVE-2017-7636 | Med | 0.40 | 6.1 | 0.01 | Jun 5, 2018 | Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to inject arbitrary web script or HTML. | ||
| CVE-2021-34361 | Med | 0.35 | 5.3 | 0.01 | Feb 25, 2022 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS… | ||
| CVE-2017-7639 | Med | 0.35 | 5.3 | 0.01 | Jun 5, 2018 | QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the settings of Proxy Server. | ||
| CVE-2021-34360 | Med | 0.34 | 5.3 | 0.00 | May 26, 2022 | A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server:… |
- risk 0.64cvss 9.8epss 0.03
QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges.
- risk 0.57cvss 8.8epss 0.01
QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections.
- risk 0.45cvss 6.9epss 0.01
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS…
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to inject arbitrary web script or HTML.
- risk 0.35cvss 5.3epss 0.01
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS…
- risk 0.35cvss 5.3epss 0.01
QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the settings of Proxy Server.
- risk 0.34cvss 5.3epss 0.00
A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server:…